Over the past year we’ve been taking a more proactive approach to reducing the number of open DNS resolvers accessible through JANET. The community’s assistance with these efforts have led to a huge reduction in their numbers. At times our investigations into specific DNS servers have revealed mistakes and oversights in the configuration of DNS servers and data that potentially leave the service with less resilience than expected.
Perhaps the most common mistakes are lame NS records – NS records that are unusable for one reason or another. In a recent test of DNS data we found that over 5% of NS records were either unresolvable or resolved to reserved IP addresses. In a few cases NS records pointed to names that were not valid in the global DNS.
You should regularly check the consistency of your DNS data and a number of freely available tools can help you with this. ZoneCheck is our tools of choice as it is freely available and the checks performed can be tailored to the unique environments found on JANET, eliminating several false positives.

